INNER CODE UNIT · Python
_check_url
tiliondev/fortress · mcp/server.py:77
async def _check_url(url: str) -> None:
"""SSRF guard for the local MCP: refuse localhost / private / cloud-metadata
targets unless the operator opts in with TILION_ALLOW_PRIVATE_EGRESS=1.
DNS resolution goes through the event loop's ASYNC resolver — a blocking
socket.getaddrinfo here would stall every concurrent tool call and could not
be cancelled by the per-tool timeout."""
if _env("ALLOW_PRIVATE_EGRESS", "0") == "1":
return
from urllib.parse import urlparse
host = (urlparse(url).hostname or "").strip("[]")
if not host:
raise ValueError(f"invalid url: {url!r}")
if host.lower() in ("localhost", "metadata.google.internal"):
raise ValueError(f"refused private/metadata host {host!r} "
"(set TILION_ALLOW_PRIVATE_EGRESS=1 to allow)")
if _ip_blocked(host): # host is already a literal IP